Re: git-am applies commit message diffs
- From
- Kristoffer Haugsbakk <kristofferhaugsbakk@fastmail.com>
- Date
- Feb 6, 2026, 08:43 UTC
- Message-ID
- <1b1f8959-aa11-4bce-8535-7245c8567d6a@app.fastmail.com>
- In-Reply-To
- <bcqvh7ahjjgzpgxwnr4kh3hfkksfruf54refyry3ha7qk7dldf@fij5calmscvm>
On Fri, Feb 6, 2026, at 08:43, Matthias Beyer wrote:
Show 22 quoted lines
> Hi, > > I am not sure whether this was already reported, searching the lore did > not yield anything for me, but I might have overlooked it... > > This was just posted on mastodon[0]: > > PSA: Did you know that it’s **unsafe** to put code diffs into your > commit messages? > > Like https:// > github.com/i3/i3/pull/6564 for example > > Such diffs will be applied by patch(1) (also git-am(1)) as part of > the code change! > > This is how a sleep(1) made it into i3 4.25-2 in Debian unstable. > > TL;DR: If you put a diff in the commit message, that diff will be > applied by git-am. > > This looks clearly like unintended and might be an attack-vector, right?
Related: https://lore.kernel.org/git/ca13705ae4817ffba16f97530637411b59c9eb19.camel@scientia.org/
But for the magic string that git-format-patch(1) uses at the start of each email.
Like Jacob said the cure is to use indentation for code blocks.
https://lore.kernel.org/git/xmqqttcmv8a6.fsf@gitster.g/#t
Indentation for code blocks: just stylistic until it isn’t. ;-)